Network port detail · UDP/TCP

31

Msg-auth
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Historically associated with late-1990s/early-2000s Windows remote-access trojans: Master's Paradise (file access, keylogging, screenshots, remote control), its Hacker's Paradise variant, and an 'Agent 31' trojan-port-database entry (threat-reported / single-source per item, tagged Likely). The IANA-assigned MSG Authentication service is dormant, so an open port 31/tcp is anomalous and worth investigating. No major active campaigns targeting port 31 were found in 2024-2026 sources reviewed.
// analyst note
The IANA service is an obsolete ARPANET-era assignment with a blank reference; treat a responsive port 31 primarily as a legacy-trojan / anomaly signal and investigate. Legitimate use is unlikely.
[ 01 ] — Context

About port 31/tcp.

Updated  ·  Confidence: Medium

Port 31/tcp is registered with IANA as msg-auth with the description "MSG Authentication," assignee and contact both listed as Robert Thomas, and blank Registration Date, Modification Date, and Reference fields (dual-registered on TCP and UDP; the 31/udp record is identical). The assignment is an ARPANET-era relic: "MSG" refers to the early host messaging program of the 1970s ARPANET, and the port was set aside for an authentication step associated with that messaging service. There is no RFC cited in the IANA registry row for this assignment, and the underlying protocol has no maintained specification — so the IANA Reference field is honestly blank rather than pointing to a standards document. For all practical purposes the IANA-assigned service is dormant: no actively maintained software is documented as using port 31/tcp for MSG Authentication, and the port sees essentially no legitimate modern deployment. The reason port 31 still surfaces for an analyst is almost entirely its legacy malware reputation. Late-1990s/early-2000s Windows remote-access trojans listened here, most notably Master's Paradise (a backdoor offering file access, keylogging, screenshots, and remote control) and its Hacker's Paradise variant, plus an "Agent 31" entry in older trojan-port databases. Those associations are historical and surface in port-reference and antivirus catalogues rather than in current campaign reporting; no significant 2024–2026 scan-wave or campaign targeting port 31 was found in the sources reviewed. Because the assigned service is obsolete and the notable history is malware, any open port 31/tcp on a public host is anomalous and worth investigating rather than a normal service; blocking inbound 31/tcp at the perimeter is reasonable unless there is an explicit operational need.

IANA assignment
msg-auth — "MSG Authentication"; reference (blank — no RFC cited in IANA registry); assignee and contact both Robert Thomas; dual-registered 31/tcp + 31/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml)
Range class
well-known (0–1023) [Confirmed]
Registration / modification date
none recorded — Registration Date and Modification Date columns are blank in the registry (not a fabricated null) [Confirmed] — IANA registry CSV
Related ports
31/udp (identical IANA record); broader cluster of legacy-assigned, malware-reputation low ports

Primary use

MSG Authentication, an authentication step tied to the early-ARPANET MSG host messaging program; no maintained specification and essentially no legitimate modern deployment [Likely] — IANA registry; historical ARPANET MSG context (RFC 254 is sometimes cited for MSG but is NOT referenced by the IANA row, so it is not treated as the assignment reference)

Common software

no actively maintained software is documented as using 31/tcp for its IANA purpose; the protocol predates modern stacks

[Likely] — SpeedGuide port 31 reference

Security implications / malware

historical association with Windows RAT/backdoors — Master's Paradise (file access, keylogging, screenshots, remote control), its Hacker's Paradise variant, and an "Agent 31" trojan-port-database entry; late-1990s–early-2000s era; no major active campaigns documented in 2024–2026 sources reviewed

[Likely/Threat-reported] — F-Secure Paradise description, community trojan-port lists

Exposure / scanning notes

not a high-value target in modern internet-wide scanning; broad scanners enumerate it in general sweeps, but no dedicated 2024–2026 scan-wave reports were found; an open 31/tcp is anomalous and warrants investigation; perimeter-block inbound unless explicitly needed

[Likely] — AuditMyPC; internet-wide-scanning literature (ZMap)

Typically seen on

legacy/compromised Windows hosts (historical RAT context); otherwise an anomaly / possible backdoor

Analyst note
The IANA service is an obsolete ARPANET-era assignment with a blank reference; treat a responsive port 31 primarily as a legacy-trojan / anomaly signal and investigate. Legitimate use is unlikely.
[ 02 ] — Context

About port 31/udp.

Updated  ·  Confidence: Medium

Port 31/udp is registered with IANA as msg-auth with the description "MSG Authentication," assignee and contact both [Robert_Thomas], and blank reference, registration-date, and modification-date fields. It is a dual registration: the same msg-auth service name and description cover both 31/tcp and 31/udp, a legacy artifact of IANA's historical practice of reserving a number on both transports at once. The assignment is one of the very old well-known entries — it predates modern IANA documentation requirements, carries no RFC or specification reference, and records no dates. No surviving public technical description of the "MSG Authentication" protocol itself has been located; the registry row is real and confirmed, but the underlying protocol is effectively undocumented, and no deployed software implementing it for its IANA-registered purpose was found. For an analyst the practical consequence is that 31/udp has no live service behind it: it sees negligible real-world UDP traffic and is not a documented target of active internet scanners. The one piece of folklore attached to "port 31" is a threat-intelligence footnote that belongs to the TCP side — port 31/tcp appears in legacy backdoor references (Agent 31, and the Master's Paradise / Hacker's Paradise family of Windows 95/98/NT-era remote-access trojans). Those entries are 1990s-era, now obsolete, and are not UDP-specific; current sources do not associate 31/udp with any malware. As a well-known port (0–1023) with no intentional service, 31/udp is low-risk but should remain closed or filtered as a matter of standard policy, and a host that answers on it is anomalous and worth investigating rather than a normal service.

IANA assignment
msg-auth — "MSG Authentication"; assignee [Robert_Thomas]; contact [Robert_Thomas]; reference blank (no RFC cited in IANA registry); registration-date and modification-date columns blank; dual-registered 31/tcp + 31/udp
[Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (CSV line 70; 31/tcp at line 69)
Range class
well-known (0–1023) [Confirmed] — IANA registry
Registration date
Unknown — IANA does not publish registration dates for this assignment (the column is blank); third-party "date registered" values are database artifacts with no authoritative source [Unknown]
Related ports
31/tcp (the dual-registered counterpart and the side carrying the historical backdoor references)

Primary use (UDP)

nominally reserved for "MSG Authentication"; no public protocol specification, no RFC, and no deployed software implementing the registered service were located, so 31/udp is functionally inert in practice

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv

Protocol over UDP

Unknown — no surviving public technical description of the MSG Authentication protocol has been found; the registry carries no reference [Unknown]

Exposure / scanning

31/udp sees negligible real-world traffic and is not a documented target of active internet scanners; no current CVEs or active exploitation campaigns targeting 31/udp were found

[Likely] — https://www.auditmypc.com/udp-port-31.asp

Security implications

low-risk legacy well-known port with no active service behind it; standard policy is to keep it closed/filtered. The backdoor folklore for "port 31" (Agent 31, Master's Paradise / Hacker's Paradise) applies to 31/tcp, is 1990s Windows-era and obsolete, and does not extend specifically to the UDP assignment [Likely] — https://www.oreilly.com/library/view/cms-security-handbook/9780470916216/appa-sec006.html ; https://www.f-secure.com/v-descs/paradise.shtml

Typically seen on

nothing legitimate on UDP; an open 31/udp is an anomaly / misconfiguration / possible decoy or backdoor

Associated software
Unknown for the IANA-registered service — no software has been found that implements MSG Authentication on 31/udp [Likely] — https://www.auditmypc.com/udp-port-31.asp
Analyst note
A responsive 31/udp is statistically rare and not a known service — treat as an anomaly worth investigating; direct any "port 31 backdoor" analysis to the 31/tcp side and note those trojans are obsolete.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
msg-auth UDP MSG Authentication 0.09%
msg-auth TCP MSG Authentication 0.00%
IANA name
msg-auth
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.